How to turn off Windows updates for good?

My solution is to run win 7 and linux. Aside from that I thought the updates could be turned off in Group Policy Editor.
 
It would appear that Windows always finds a way to update.

For the BI install, that computer is 100% isolated from the net. In my case it is also 100% effective. Zero updates. For others, this solution is not appropriate for their needs.
 
Last edited:
  • Like
Reactions: bigredfish
There's got to be a way to shut them off. A large company with an IT department can't let updates not under their control go through.
 
  • Like
Reactions: JNDATHP
Apparently not, because half the world grinded to a halt the other day with that Crowdstrike update.
I think that wasn't a windows update from microsoft. The crowdstrike stuff is a different product.
 
  • Like
Reactions: Valiant
OPTION 3 of the 7 ways listed, works well. Yet, if needed you can still manually run windows update if needed.


Definitely do not remove C:\Windows\system32\svchost.exe executable from Windows, as this is used for all services on the computer, including BI.
 
  • Like
Reactions: bigredfish
Apparently not, because half the world grinded to a halt the other day with that Crowdstrike update.
No, those companies (Delta, others) failed for simple reason of ignoring decades old lessons regarding handling ALL system updates (OS and security, plus others, especially anything with local admin/Ring 0 access). Any decently run enterprise configures their updates to hit Dev environments first, the Test/QA, and only a bit after that, Production systems. That's been true every place I worked for last 30+ years
Oh, and if I heard correctly the current CEO at CrowdStrike was also at MacAfee when same thing happened over 10 years ago ??? hope this isn't 'fake news' ... just sloppy processes regardless

Stopping OS updates makes all kinds of sense for completely isolated networks. BUT, for any devices reaching the Internet (email, browsing, etc) not having an update plan is just asking to get hacked. Even an enterprise class firewall for home won't help. There are work-arounds, but in reality, they are more cumbersome than a decent backup routine, not installing most updates on Day 1
Sorry not updating is simply trading one problem for an equal other one in most consumer situations. You aren't actually helping yourself. though it might have a certain in-the-moment emotional appeal

With that said, I do NOT immediately install updates upon release, I'm set to let them 'bake' a bit. And all of my Internet communications are done on Virtual Machines where it is easy to revert an OS image to a prior state.